Privacy Policy
Effective date: July 8, 2026
Misma is a personal savings and money-habit app developed by Overstruck UG (haftungsbeschränkt) (“we”, “us”, or “our”). This Privacy Policy explains what information Misma processes when you use the app, and the rights you have.
Misma is intended for users aged 18 and older.
1. Who we are (Controller)
The controller responsible for your personal data is:
Overstruck UG (haftungsbeschränkt)
VoĂźheider Str. 98A
32657 Lemgo
Germany
Email: support@overstruck.net
2. Information we process
Account data. Using Misma requires an account. We process your email address and a password. Your password is stored only in hashed form by our authentication provider and is never visible to us.
Your savings and in-app data. The information you enter in the app — such as savings entries, goals, portfolio values, and your world and game progress — is stored in your own private iCloud (Apple CloudKit) and on your device. This data stays in your personal iCloud account; we do not store it on our servers and cannot browse it.
Subscription data. If you subscribe to Misma Plus, your subscription status is processed and linked to your account identifier so we can unlock premium features.
Referral data. If you use the referral feature, we store your referral code and a record linking the referrer and the referred user, so we can grant the free-month reward and prevent abuse. To limit rewards to one per physical device, we use Apple DeviceCheck, which lets us set and read two bits associated with your device without otherwise identifying you.
Technical data. When the app communicates with our backend, standard connection data such as your IP address is processed transiently to deliver the service and to keep it secure.
Website (password reset). If you reset your password on our website, our authentication provider temporarily stores session information in your browser’s local storage to complete the reset. This is used only to carry out the reset; it is not used for tracking, and our website does not set cookies.
3. How we use information and our legal bases
We process the above data to:
- create and operate your account and provide the app (Art. 6(1)(b) GDPR — performance of a contract);
- manage subscriptions and purchases (Art. 6(1)(b) GDPR);
- operate the referral program and prevent abuse, including via Apple DeviceCheck (Art. 6(1)(f) GDPR — our legitimate interest in a fair, non-abusable program);
- keep the service secure, troubleshoot problems, and prevent fraud (Art. 6(1)(f) GDPR); and
- comply with our legal obligations (Art. 6(1)(c) GDPR).
4. No advertising, no tracking, no analytics
Misma does not show advertisements. We do not use advertising identifiers, and we do not use third-party analytics, tracking, or profiling tools in the app. We do not sell or share your personal information, and we do not build advertising profiles about you.
5. In-app purchases and subscriptions
Misma offers an optional subscription, Misma Plus. Payments are processed by the Apple App Store; we never receive or store your payment card details. Subscription status is managed through RevenueCat.
Apple and RevenueCat process purchase-related information under their own privacy policies:
6. Service providers we use
We rely on a small number of providers to run Misma. They process data on our behalf or as independent controllers as described in their own privacy policies:
- Apple — App Store, iCloud/CloudKit storage of your in-app data, DeviceCheck, and in-app purchases (privacy policy).
- Supabase — authentication and our backend database (account and referral data) (privacy policy).
- RevenueCat — subscription management (privacy policy).
- Fly.io — hosting of our backend (privacy policy).
7. International data transfers
We are based in Germany and prefer processing within the European Union. Some providers (for example RevenueCat and Apple) may process data in the United States. Where personal data is transferred outside the European Economic Area, it is protected by appropriate safeguards such as the EU Standard Contractual Clauses or an adequacy decision.
8. Data retention
We keep your account data for as long as you have a Misma account. Referral records are kept for as long as needed to operate the referral program and prevent abuse. Your savings and in-app data remain in your private iCloud until you delete them or delete the app — that data is under your control.
When you delete your account, we delete your account data from our backend. Data stored in your iCloud is managed by you through your device and Apple ID.
9. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to certain processing. Where processing is based on consent, you can withdraw it at any time. You also have the right to lodge a complaint with a data protection supervisory authority.
To exercise any of these rights, contact us at support@overstruck.net.
You can also act directly in the app: delete your account and its backend data via Settings, and delete your on-device and iCloud data via the app’s data-deletion option.
10. Data security
We protect data in transit with encryption (HTTPS) and use reputable providers. Passwords are stored only in hashed form by our authentication provider. Despite our efforts, no method of electronic storage or transmission is completely secure.
11. Children’s privacy
Misma is intended for users aged 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, please contact us at support@overstruck.net and we will take appropriate action.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make changes, we will update the effective date shown above. Your continued use of Misma after changes take effect means the updated Privacy Policy applies.
13. Contact
For any privacy questions or requests, please contact:
Overstruck UG (haftungsbeschränkt)
VoĂźheider Str. 98A
32657 Lemgo
Germany
Email: support@overstruck.net